SELECT * FROM `site_users` WHERE `user_id`='1003''You have an error in your
SQL syntax;
check the manual that corresponds to your MySQL server version for the
right syntax to use near ''1003''' at line 1
This of course means you can do some slightly dodgy refected XSS:
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.